CVE-2025-66075
Description
Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in WP Cookie Notice plugin <=4.0.3 allows unprivileged attackers to exploit broken access controls, potentially altering site configuration.
Root
Cause The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin (versions up to 4.0.3) contains a missing authorization vulnerability [1]. The plugin fails to properly verify access control permissions, allowing exploited incorrectly configured access control security levels. This is classified as a Broken Access Control issue [1].
Exploitation
Attackers can exploit this flaw remotely without prior authentication, as the missing authorization check allows unprivileged users to execute functions that should be restricted to higher-privileged roles [1]. The vulnerability is reportedly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of size [1].
Impact
The severity is rated as Medium (CVSS 4.3) but the Patchstack advisory notes a low severity impact within the WordPress context, deeming exploitation unlikely [1]. However, successful exploitation could allow attackers to perform actions that require administrative privileges, potentially compromising site configuration.
Mitigation
The vulnerability has been patched in version 4.0.4 [1]. Users are strongly advised to update immediately. Patchstack subscribers can enable auto-updates for the plugin to stay protected [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=4.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.